Back to Articles
Thought Leadership6 min read

RegTech Adoption Isn't Stalling on Technology. It's Stalling on Who Answers for the Decision.

Analysis of

Fredrik Gröndahl
RegTech Adoption Isn't Stalling on Technology. It's Stalling on Who Answers for the Decision.

A compliance officer at a Luxembourg management company can accept a vendor's KYC risk score in eleven seconds. Explaining that score to a CSSF inspector six months later, after the client turns out to be a problem, takes considerably longer, and the officer, not the vendor, is the one giving the explanation.

New research says that asymmetry, not integration cost or feature gaps, is what is actually slowing RegTech adoption down.

On 20 August, fintech.global published the second half of its analysis of "The Global State of RegTech 2026", a report co-authored by RegTech Analyst and Parker Lawrence Research. The headline piece leads with the expected culprits: 52% of institutions and 58% of vendors name legacy system integration as a barrier, and 50% of vendors, against just 22% of institutions, point to fragmented internal ownership of the vendor relationship.

The deeper finding sits underneath those numbers. As Bhavin Shah, CEO of Sherlocq, puts it in the piece, third-party RegTech adoption is less a technology problem than a confidence problem. Duco Van Lanschot, CEO of Duna, is more specific about where that confidence problem comes from: a new tool can speed up onboarding and improve the customer experience, but if it gets a decision wrong, it is the compliance officer who answers for it, by name, so caution is the rational response. Andrew Davies of ComplyAdvantage frames it as a structural fact rather than a psychological one: institutions can outsource a process, but they cannot outsource the risk.

That is the real subject of this piece, not why RegTech sales cycles are slow, but what a vendor's product has to actually contain before that caution becomes unnecessary.

The Integration Complaint Is a Symptom, Not the Disease

Legacy integration tops both institution and vendor lists of adoption barriers, and it is a real cost. But Anthony Quinn, CEO of Arctic Intelligence, reframes the finding in a way worth taking seriously: financial institutions are not buying software, they are buying confidence, and technology is no longer the limiting factor, perceived implementation risk is. Integration friction is easy to quantify, so it becomes the answer procurement teams give when asked what is slowing them down. Accountability exposure is harder to quantify, so it goes underreported in surveys even when it is the thing actually driving the caution. Firms will spend six months in a proof of concept for a tool that would take two weeks to integrate, because the real question they are answering is not whether it connects to their core system, but whether they can still defend the decision if it goes wrong.

Liability Does Not Move With the Contract

Under AMLR, and the equivalent FSC framework in Mauritius, the obligated entity remains the obligated entity regardless of which vendor's model produced the risk score, the document classification, or the screening match. A management company that outsources KYC processing to a RegTech platform has not outsourced its regulatory exposure, it has added a layer between itself and the evidence. Allison Lagosh of Saifr states the resulting principle plainly: regulatory accountability cannot be outsourced. This is not a compliance department being risk averse for its own sake. It is a correct reading of how supervisory liability actually works. A CSSF or FSC examiner does not ask whether the vendor's algorithm was accurate on average, the examiner asks whether the specific decision on the specific file in front of them was reasonable, and whether the firm can show its reasoning.

Buyers Are Vetting the Wrong Criteria

The research contains a disconnect worth naming directly. Only half of compliance leaders told ComplyAdvantage's 2026 State of Financial Crime Report that they were confident AI regulation in their jurisdiction would help them explain an AI-driven decision after the fact, and only 59% report having a comprehensive AI assurance programme covering model risk governance. Yet when the same leaders were asked what criteria actually drive their choice of AI vendor, explainability ranked fourth, cited by only 43%. Firms report anxiety about defending a decision, then buy on price, integration ease, and vendor reputation instead of on whether the tool's output is something a human can independently reconstruct and stand behind. The criteria buyers say they worry about and the criteria they actually screen for are not the same list.

What Closes the Gap Is Structural, Not Reassurance

None of this is solved by a vendor producing a better case study or a more confident sales deck. It is solved by whether the tool's output is, by design, something the compliance officer can defend without the vendor in the room: source documents attached to the decision, the specific criteria applied, a version history of the policy in force at the time, and reasoning that reads as an audit trail rather than a score. A risk score with no underlying evidence file is a black box regardless of how accurate it is on average, and no amount of vendor confidence building changes that a compliance officer cannot sign their name to a number they cannot independently defend. A risk score attached to a reconstructible evidence chain is a different product, even if the underlying model is identical.

What This Means for Management Companies and TCSPs

When evaluating a RegTech vendor, the integration questionnaire is the easy part. The harder and more consequential question is whether the vendor can produce, for a single sampled file, an evidence package that would satisfy a CSSF or FSC examiner without the vendor's own staff present to explain it. Ask for that sample before the contract, not after the first inspection. If the answer is a dashboard screenshot and a confidence score, the tool is buying speed at the cost of exactly the accountability exposure the research says is the real barrier. If the answer is a document trail an officer could defend independently, the procurement risk that is actually stalling adoption across the industry has been addressed, whatever the integration timeline turns out to be.

The RegTech industry has largely diagnosed its own adoption problem as a trust deficit, to be closed with better onboarding, references, and marketing. That diagnosis is comfortable and wrong. Trust is not what a compliance officer needs from a vendor, independent verification is. A tool that cannot hand over evidence a human can check without the vendor's help is asking for exactly the kind of blind faith that the accountability structure of AMLR and the FSC framework was built to prevent. Firms that keep asking vendors to prove they are trustworthy are asking the wrong question. The right one is whether the output can be defended without the vendor in the room, and that is a property of the data architecture, not the sales relationship.

Fidify builds KYC and AML workflows around document-driven evidence rather than opaque scores, so every decision carries the file that supports it. Talk to us about what an audit-ready evidence trail should look like for your firm.